nginx+keepalived構建雙主負載均衡代理服務器

引言html

Nginx是一個高性能的代理服務器,單臺Nginx容易出現單點故障,使用keepalived能夠實現Nginx的故障轉移,保證了網站的高可用性前端

1、使用Nginx+keepalived的兩種方案nginx

一、主從模式vim

使用一個VIP,前端有2臺服務器,一主一從,正常狀況下是主服務器提供服務只有當主服務器不能正常提供服務以後,從服務器才提供服務,此時總會有一臺服務器是空閒狀態。
bash

二、雙主模式服務器

使用兩個VIP,前段有2臺服務器,互爲主從,兩臺服務器同時工做,不存在資源浪費狀況。同時在前段的DNS服務器對網站作多條A記錄,實現了Nginx的負載均衡,當一臺服務器故障時候,資源會轉移到另外一臺服務器,繼續提供服務,在大型的網站中多數都使用此種架構。在此使用主主模式配置Nginx+keepalived的高可用性。網絡

2、準備實驗環境架構

一、服務器IP地址規劃負載均衡

VIP:172.16.10.8運維

VIP:172.16.10.9

Keepalived1:172.16.10.1

Keepalived2:172.16.10.2

二、服務器操做系統

Keepalived1:Centos 6.4 x86_64

Keepalived2:Centos 6.4 x86_64

三、網絡拓撲圖

143733168.png


四、修改主機名以及hosts文件keepalived1

####keepalived1 server############
sed -i 's@\(HOSTNAME=\).*@\1keepalived1@g'/etc/sysconfig/network
hostname keepalived1
[root@keepalived1 ~]# echo "172.16.10.1 keepalived1">> /etc/hosts
[root@keepalived1 ~]# echo "172.16.10.2 keepalived2">> /etc/hosts
[root@keepalived1 ~]# ssh-keygen -t rs
[root@keepalived1 ~]# ssh-copy-id -i .ssh/id_rsa.pub keepalived2
[root@keepalived1 ~]# scp /etc/hosts keepalived1:/etc/
####keepalived2 server############
sed -i 's@\(HOSTNAME=\).*@\1keepalived2@g'/etc/sysconfig/network
hostname keepalived2
[root@keepalived2 ~]# ssh-keygen -t rsa
[root@keepalived2 ~]# ssh-copy-id -i .ssh/id_rsa.pub keepalived1

3、編譯安裝Nginx

[root@keepalived1 ~]# yum install openssl-devel pcre-devel gcc -y
[root@keepalived1 ~]# tar xf nginx-1.4.2.tar.gz -C /usr/local/
[root@keepalived1 ~]# cd /usr/local/
[root@keepalived1 local]# groupadd -r nginx
[root@keepalived1 local]# useradd -r -g nginx nginx
[root@keepalived1 local]# cd nginx-1.4.2/
[root@keepalived1 nginx-1.4.2]# ./conf
conf/      configure
[root@keepalived1 nginx-1.4.2]# ./configure \
> --prefix=/usr \
>    --sbin-path=/usr/sbin/nginx \
>    --conf-path=/etc/nginx/nginx.conf \
>    --error-log-path=/var/log/nginx/error.log \
>    --http-log-path=/var/log/nginx/access.log \
>    --pid-path=/var/run/nginx/nginx.pid  \
>    --lock-path=/var/lock/nginx.lock \
>    --user=nginx \
>    --group=nginx \
>    --with-http_ssl_module \
>    --with-http_flv_module \
>    --with-http_stub_status_module \
>    --with-http_gzip_static_module \
>    --http-client-body-temp-path=/var/tmp/nginx/client/ \
>    --http-proxy-temp-path=/var/tmp/nginx/proxy/ \
>    --http-fastcgi-temp-path=/var/tmp/nginx/fcgi/ \
>    --http-uwsgi-temp-path=/var/tmp/nginx/uwsgi \
>    --http-scgi-temp-path=/var/tmp/nginx/scgi \
>    --with-pcre
[root@keepalived1 nginx-1.4.2]# make && make install
[root@keepalived1 nginx-1.4.2]# vim /etc/init.d/nginx
#!/bin/sh
#
# nginx - this script starts and stops the nginx daemon
#
# chkconfig:   - 85 15
# description:  Nginx is an HTTP(S) server, HTTP(S) reverse \
#               proxy and IMAP/POP3 proxy server
# processname: nginx
# config:      /etc/nginx/nginx.conf
# config:      /etc/sysconfig/nginx
# pidfile:     /var/run/nginx.pid
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
# Source function library.
. /etc/rc.d/init.d/functions
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
# Source networking configuration.
. /etc/sysconfig/network
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
# Check that networking is up.
[ "$NETWORKING" = "no" ] && exit 0
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
nginx="/usr/sbin/nginx"
prog=$(basename $nginx)
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
NGINX_CONF_FILE="/etc/nginx/nginx.conf"
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
[ -f /etc/sysconfig/nginx ] && . /etc/sysconfig/nginx
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
lockfile=/var/lock/subsys/nginx
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
make_dirs() {
   # make required directories
   user=`nginx -V 2>&1 | grep "configure arguments:" | sed 's/[^*]*--user=\([^ ]*\).*/\1/g' -`
   options=`$nginx -V 2>&1 | grep 'configure arguments:'`
   for opt in $options; do
       if [ `echo $opt | grep '.*-temp-path'` ]; then
           value=`echo $opt | cut -d "=" -f 2`
           if [ ! -d "$value" ]; then
               # echo "creating" $value
               mkdir -p $value && chown -R $user $value
           fi
       fi
   done
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
start() {
    [ -x $nginx ] || exit 5
    [ -f $NGINX_CONF_FILE ] || exit 6
    make_dirs
    echo -n $"Starting $prog: "
    daemon $nginx -c $NGINX_CONF_FILE
    retval=$?
    echo
    [ $retval -eq 0 ] && touch $lockfile
    return $retval
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
stop() {
    echo -n $"Stopping $prog: "
    killproc $prog -QUIT
    retval=$?
    echo
    [ $retval -eq 0 ] && rm -f $lockfile
    return $retval
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
restart() {
    configtest || return $?
    stop
    sleep 1
    start
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
reload() {
    configtest || return $?
    echo -n $"Reloading $prog: "
    killproc $nginx -HUP
    RETVAL=$?
    echo
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
force_reload() {
    restart
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
configtest() {
  $nginx -t -c $NGINX_CONF_FILE
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
rh_status() {
    status $prog
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
rh_status_q() {
    rh_status >/dev/null 2>&1
}
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              
case "$1" in
    start)
        rh_status_q && exit 0
        $1
        ;;
    stop)
        rh_status_q || exit 0
        $1
        ;;
    restart|configtest)
        $1
        ;;
    reload)
        rh_status_q || exit 7
        $1
        ;;
    force-reload)
        force_reload
        ;;
    status)
        rh_status
        ;;
    condrestart|try-restart)
        rh_status_q || exit 0
            ;;
    *)
        echo $"Usage: $0 {start|stop|status|restart|condrestart|try-restart|reload|force-reload|configtest}"
        exit 2
esac
[root@keepalived1 nginx-1.4.2]# chmod +x /etc/init.d/nginx
[root@keepalived1 nginx-1.4.2]# service nginx start

注意在此只上傳了keepalived1的代碼,keepalived2也須要一樣的操做

一、修改默認網頁以方便後期測試

###############keepalived1######################
[root@keepalived1 ~]# echo "<h1>keepalived1</h1>" > /usr/html/index.html
###############keepalived2######################
[root@keepalived2 ~]# echo "<h1>keepalived2</h1>" > /usr/html/index.html

4、 安裝與配置keepalived

一、安裝keepalived

###############keepalived1######################
[root@keepalived1 ~]# yum install keepalived -y
###############keepalived2######################
[root@keepalived2 ~]# yum install keepalived -y

二、修改配置文件

[root@keepalived1 keepalived]# grep -v "#" /etc/keepalived/keepalived.conf
! Configuration File for keepalived
global_defs {
   notification_email {
     root@localhost
   }
   notification_email_from Alexandre.Cassen@localhost
   smtp_server 127.0.0.1
   smtp_connect_timeout 30
   router_id LVS_DEVEL
}
 vrrp_script chk_nginx {        #監控nginx腳本
    script "killall -0 nginx"   #監控nginx進程
    interval 1                  #監控間隔
    weight -2                   #優先級-2
}
vrrp_instance VI_1 {
    state MASTER                 #主server 
    interface eth0             
    virtual_router_id 80
      priority 100               #優先級
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 1111
    }
    virtual_ipaddress {
        172.16.10.8            #定義vip
    }
    track_script {
    chk_nginx                 #跟蹤腳本
}
    notify_master "/etc/keepalived/notify8.sh master"  #定義郵件通知
    notify_backup "/etc/keepalived/notify8.sh backup"
    notify_fault "/etc/keepalived/notify8.sh fault"
}
                                                                                                                                                            
vrrp_instance VI_2 {
    state BACKUP            #從server
    interface eth0
    virtual_router_id 81
    priority 99
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 1111
    }
    virtual_ipaddress {
        172.16.10.9
    }
    track_script {
    chk_nginx
}
    notify_master "/etc/keepalived/notify9.sh master" #定義郵件通知
    notify_backup "/etc/keepalived/notify9.sh backup"
    notify_fault "/etc/keepalived/notify9.sh fault"
}
[root@keepalived1 keepalived]#

三、編輯郵件通知腳本(notify8.sh notify9.sh)

#####################notify8.sh##############
[root@keepalived1 keepalived]# cat notify8.sh
#!/bin/bash
# Author: xiaodong <xiaodong@foxmail.com>
# description: An example of notify script
#
vip=172.16.10.8
contact='root@localhost'
notify() {
    mailsubject="`hostname` to be $1: $vip floating"
    mailbody="`date '+%F %H:%M:%S'`: vrrp transition, `hostname` changed to be $1"
    echo $mailbody | mail -s "$mailsubject" $contact
}
case "$1" in
    master)
        notify master
        /etc/rc.d/init.d/nginx start
        exit 0
    ;;
    backup)
        notify backup
        /etc/rc.d/init.d/nginx stop
       exit 0
    ;;
    fault)
        notify fault
        exit 0
    ;;
    *)
        echo 'Usage: `basename $0` {master|backup|fault}'
        exit 1
    ;;
esac
####################notfiy9.sh#################
[root@keepalived1 keepalived]# cat notify9.sh
#!/bin/bash
# Author: xiaodong <xiaodong@foxmail.com>
# description: An example of notify script
#
vip=172.16.10.9
contact='root@localhost'
notify() {
    mailsubject="`hostname` to be $1: $vip floating"
    mailbody="`date '+%F %H:%M:%S'`: vrrp transition, `hostname` changed to be $1"
    echo $mailbody | mail -s "$mailsubject" $contact
}
case "$1" in
    master)
        notify master
         exit 0
    ;;
    backup)
        notify backup
       exit 0
    ;;
    fault)
        notify fault
        exit 0
    ;;
    *)
        echo 'Usage: `basename $0` {master|backup|fault}'
        exit 1
    ;;
esac
[root@keepalived1 keepalived]# chmod +x notify8.sh
[root@keepalived1 keepalived]# chmod +x notify9.sh


四、複製配置文件到keepalived2,並作修改.

[root@keepalived1 keepalived]# scp -p  keepalived.conf notify8.sh notify9.sh keepalived2:/etc/keepalived/
[root@keepalived2 keepalived]# grep -v "#" /etc/keepalived/keepalived.conf
! Configuration File for keepalived
global_defs {
   notification_email {
     root@localhost
   notification_email_from Alexandre.Cassen@localhost
   smtp_server 127.0.0.1
   smtp_connect_timeout 30
   router_id LVS_DEVEL
}
  vrrp_script chk_nginx {
   script "killall -0 nginx "
    interval 1
    weight -2
}
vrrp_instance VI_1 {
    state BACKUP                   #改成backup
    interface eth0
    virtual_router_id 80
    priority 99                    #改成99
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 1111
    }
    virtual_ipaddress {
        172.16.10.8
    }
    track_script {
        chk_nginx
}
    notify_master "/etc/keepalived/notify.sh master"
    notify_backup "/etc/keepalived/notify.sh backup"
    notify_fault "/etc/keepalived/notify.sh fault"
}
vrrp_instance VI_2 {
    state MASTER              #改成MASTER
    interface eth0
    virtual_router_id 81
    priority 100              #改成100
    advert_int 1
    authentication {
        auth_type PASS
        auth_pass 1111
    }
    virtual_ipaddress {
        172.16.10.9
    }
    track_script {
        chk_nginx
}
    notify_master "/etc/keepalived/notify9.sh master"
    notify_backup "/etc/keepalived/notify9.sh backup"
    notify_fault "/etc/keepalived/notify9.sh fault"
}

註釋:此處使用本地的郵件服務器接受郵件,若是須要用其它郵件服務器請修改contact='root@localhost'

五、啓動keepalived服務

###############keepalived1######################
[root@keepalived1 ~]# service keepalived start
###############keepalived2######################
[root@keepalived2 ~]# service keepalived start


六、查看兩個節點的vip是否啓動正常

135210698.png

135213410.png

5、測試nginx+keepalived的高可用性

一、使用遊覽器訪問測試

135523727.png

135526139.png

二、模擬節點出現故障,nginx服務器是否能自動轉移

[root@keepalived1 keepalived]# service keepalived stop

135843406.png

135845568.png

經過以上測試,節點出現故障的時候,服務能夠自動轉移到備用節點上

三、測試主節點服務down掉以後,備用節點服務是否能正常運行

[root@keepalived1 keepalived]# service keepalived start
[root@keepalived1 keepalived]# killall nginx

140445250.png

140447489.png

經過以上測試,實現了Nginx的高可用性,可是,運維人員是否能第一時間得知服務器出現故障,這時候就須要查看郵件了

四、查看郵件是否收到信息

[root@keepalived1 keepalived]# mail   #查看郵件命令
Heirloom Mail version 12.4 7/29/08.  Type ? for help.
"/var/spool/mail/root": 1 message 1 new
>N  1 root                  Wed Sep 25 20:15  18/728   "keepalived1 to be backup: 172.16.10.8 floating"
& 1
Message  1:
From root@keepalived1.localdomain  Wed Sep 25 20:15:46 2013
Return-Path: <root@keepalived1.localdomain>
X-Original-To: root@localhost
Delivered-To: root@localhost.localdomain
Date: Wed, 25 Sep 2013 20:15:46 +0800
To: root@localhost.localdomain
Subject: keepalived1 to be backup: 172.16.10.8 floating
User-Agent: Heirloom mailx 12.4 7/29/08
Content-Type: text/plain; charset=us-ascii
From: root@keepalived1.localdomain (root)
Status: R
2013-09-25 20:15:46: vrrp transition, keepalived1 changed to be backup
& quit                               #退出郵件

五、當nginx服務啓動以後,主節點恢復

[root@keepalived1 keepalived]# service nginx start
[root@keepalived1 keepalived]# mail
Heirloom Mail version 12.4 7/29/08.  Type ? for help.
"/var/spool/mail/root": 2 messages 1 unread
    1 root                  Wed Sep 25 20:15  19/739   "keepalived1 to be backup: 172.16.10.8 floating"
>U  2 root                  Wed Sep 25 20:16  19/738   "keepalived1 to be master: 172.16.10.8 floating"
&
Message  2:
From root@keepalived1.localdomain  Wed Sep 25 20:16:22 2013
Return-Path: <root@keepalived1.localdomain>
X-Original-To: root@localhost
Delivered-To: root@localhost.localdomain
Date: Wed, 25 Sep 2013 20:16:22 +0800
To: root@localhost.localdomain
Subject: keepalived1 to be master: 172.16.10.8 floating
User-Agent: Heirloom mailx 12.4 7/29/08
Content-Type: text/plain; charset=us-ascii
From: root@keepalived1.localdomain (root)
Status: RO
2013-09-25 20:16:22: vrrp transition, keepalived1 changed to be master

Nginx+keepalived的高可用負載均衡配置完成。

本博客至此結束,若有不足之處,望你們多提寶貴意見!!!!

相關文章
相關標籤/搜索